Senior Azure Cloud DevSecOps Engineer
Azure Cloud & DevOps Practice • Enterprise Platform Engineering
Total Experience: 8+ years
Relevant Experience: 5+ years (minimum 2 years in lead / architect capacity)
Primary Platform: Microsoft Azure
Engagement Type: Enterprise production, multi-region, regulated cloud environments
Required Certification: AZ-400 DevOps Engineer Expert (minimum for senior role)
ABOUT THE ROLE & ORGANISATION
We are building a secure, scalable Azure platform that supports critical enterprise operations and enables faster, more reliable delivery.
The DevOps team owns infrastructure lifecycle, CI/CD, Kubernetes, observability, and platform reliability in close partnership with engineering, security, and operations teams.
ROLE OVERVIEW
The Senior Azure Cloud DevSecOps Engineer leads the design and improvement of secure, scalable, highly available Azure infrastructure.
This role combines platform engineering, automation, CI/CD, observability, DevSecOps, and technical leadership in regulated enterprise environments.
KEY SKILLS & TECHNOLOGY STACK
Category
Technologies / Tools
Cloud Platform
Microsoft Azure
Azure Services
AKS, API Management, Application Gateway, Front Door, VNet, Private Link, Key Vault, Service Bus, Event Hub, Azure Monitor, Log Analytics
IaC & Automation
Terraform (modular, remote state, env separation), Bash, PowerShell, Python
CI/CD
GitLab CI/CD (pipelines, runners, registries, reusable templates), Azure DevOps, Jenkins
Containers & K8s
AKS, Helm, Docker, Service Mesh (Istio / Linkerd — advantage), GitOps: ArgoCD / Flux
Observability
Dynatrace (full-stack, distributed tracing, dashboards, alerting), Azure Monitor, Log Analytics
Security & Identity
Entra ID (Azure AD), RBAC, Managed Identities, Key Vault, Azure Policy, Defender for Cloud, NSG, Private Endpoints
Vulnerability Mgmt
Qualys, cloud compliance & posture management tooling
Networking
VNet, Subnets, NSG, DNS, Load Balancing, Private Endpoints, Application Gateway, Front Door
FinOps
Cloud cost optimization, resource rightsizing, reserved capacity planning
KEY RESPONSIBILITIES
Cloud Architecture & Platform Ownership
-
Own Azure cloud and DevOps architecture, standards, and reusable reference patterns.
-
Design and maintain Terraform modules for production-grade, multi-region infrastructure with clear environment separation.
-
Govern core Azure services including AKS, API Management, Application Gateway, Front Door, networking, Key Vault, Service Bus, and Event Hub.
-
Optimize cost, utilization, performance, and reliability through FinOps practices.
CI/CD & Delivery Engineering
-
Build GitLab CI/CD pipelines, templates, runners, registries, and multi-environment deployments.
-
Integrate security controls (SAST, secret scanning, container image scanning) into deployment and automation workflows.
-
Implement GitOps approaches using ArgoCD or Flux for declarative, auditable Kubernetes delivery.
Kubernetes & Container Platform
-
Manage AKS clusters, container workloads, ingress, autoscaling, and service mesh adoption.
-
Maintain Helm chart libraries and containers build pipelines for multi-environment application delivery.
-
Troubleshoot Kubernetes issues and implement scalable long-term fixes.
Observability & Reliability
-
Drive full-stack observability with Dynatrace, Azure Monitor, and Log Analytics, covering tracing, dashboards, SLOs, and alerting.
-
Define and enforce SLOs, error budgets, and reliability standards across the platform.
-
Lead incident response, on-call triage, and blameless post-incident reviews.
Security & Compliance (DevSecOps)
-
Embed security across the platform through Key Vault secret management, network policies, least-privilege RBAC, and DevSecOps controls.
-
Manage cloud security posture using Entra ID, Managed Identities, Azure Policy, Defender for Cloud, NSG, and Private Endpoints.
-
Support vulnerability remediation and cloud governance initiatives using Qualys and complementary compliance monitoring platforms.
Leadership & Collaboration
-
Lead and mentor DevOps engineers while promoting ownership and continuous improvement.
-
Collaborate with engineering, product, and business stakeholders to improve the inner developer loop and overall developer experience.
-
Document architectural decisions and platform standards clearly.
REQUIRED QUALIFICATIONS
-
5+ years in DevOps, Cloud, or SRE roles, including 2+ years as lead or architect.
-
Hands-on Azure production experience across AKS, API Management, Application Gateway, Front Door, networking, Key Vault, Service Bus, and Event Hub.
-
Proficiency in Terraform — modular design, remote state management, and environment separation.
-
Expertise in running Kubernetes in production (AKS specifically) with hands-on Helm and containerized application experience.
-
GitLab CI/CD end-to-end: pipelines, runners, environments, container registries, and reusable pipeline templates.
-
Strong cloud networking skills: VNet, subnets, NSG, Private Endpoints, DNS, and load balancing.
-
Azure security and identity expertise: Entra ID, RBAC, Managed Identities, Key Vault, Azure Policy, and Defender for Cloud.
-
Proficiency in scripting with Bash, PowerShell, or Python.
-
Strong troubleshooting, root-cause analysis, and production support skills.
PREFERRED QUALIFICATIONS
-
Exposure to multi-cloud platforms.
-
Familiarity with Azure Devops; GitOps approaches using ArgoCD or Flux.
-
FinOps experience: cloud cost optimization, resource rightsizing, reserved capacity planning.
-
Exposure to regulated or financial services environments.
-
Knowledge of service mesh technologies (i.e. Istio, Linkerd).
-
Graduate or postgraduate degree (or equivalent qualification).
-
Experience supporting global, cross-functional operational teams.
CERTIFICATIONS
Required (Senior Level)
-
AZ-400 — Microsoft DevOps Engineer Expert (minimum requirement for this role)
Strongly Recommended
-
AZ-104 — Microsoft Azure Administrator Associate
-
AZ-305 — Microsoft Azure Solutions Architect Expert
-
CKA — Certified Kubernetes Administrator
Advantageous
-
Dynatrace Professional Certification
-
HashiCorp Terraform Associate / Professional
-
GitLab Certified CI/CD Associate or Professional